Skip to main content
Whistleblower Protection

Group-level reporting office

A group-level reporting office pools the internal whistleblowing function at one central group company, which acts as a mandated third party for the affiliated entities under Section 14 (1) of the German Whistleblower Protection Act (HinSchG).

A group-level reporting office exists where the affiliated companies do not each run their own internal reporting office, but a central unit – typically group compliance at the parent company or a shared service entity – receives and handles reports on behalf of several group companies. In Germany this model rests on Section 14 (1) sentence 1 HinSchG, which allows an employer to entrust a third party with the duties of the internal reporting office; the explanatory memorandum expressly names another group company as such a third party. It must be distinguished from the joint reporting office under Section 14 (2) HinSchG, which is open only to employers with 50 to 249 employees and implements Article 8 (6) of Directive (EU) 2019/1937.

Whether this broad German reading is compatible with EU law remains contested. In guidance given to member states (statements by DG Justice in 2021) the European Commission took the view that every legal entity with 50 or more employees must maintain its own internal reporting channel; a group-wide channel may only exist in addition to the local one, and the reporting person must be free to choose where to report. The German legislator did not follow that interpretation. There is still no ruling by the Court of Justice of the European Union on the point, so groups that centralise reporting entirely carry a residual risk should the stricter reading prevail.

Regardless of that dispute, the duties of each individual employer remain untouched. Under Section 14 (1) sentence 2 HinSchG, mandating a third party does not release the employer from taking appropriate measures itself to stop an identified breach; accountability and the exposure to fines stay with the subsidiary. The central unit must act independently and with the necessary expertise (Section 15 HinSchG), observe the confidentiality requirement of Section 8 HinSchG and meet the deadlines of Section 17 HinSchG. Data protection also needs a proper basis, because the GDPR grants no group privilege for sharing report data. In practice a hybrid design works best: a group-wide channel combined with locally named contact persons and a documented right of the reporting person to choose.

Legal Basis

Sections 14 (1) and 14 (2) HinSchG; Sections 8, 15, 17 HinSchG; Article 8 (3) to (6) of Directive (EU) 2019/1937

Practical Example

A mechanical engineering group with a holding company and six German subsidiaries – four of them with more than 250 employees – wants to pool the reporting office at group compliance. The compliance officer signs a written mandate agreement with each subsidiary under Section 14 (1) HinSchG plus a data processing agreement setting out access rights, retention periods and how findings are passed to the local management. In addition, every subsidiary names a local contact who can receive reports directly; the intranet lists both routes as well as the federal external reporting office. The group is therefore compliant even if the European Commission's stricter reading prevails, and responsibility for follow-up measures demonstrably stays with the company concerned.

FAQ

Under German law yes: Section 14 (1) HinSchG permits mandating a third party, and the explanatory memorandum expressly names another group company as an eligible third party. The European Commission reads Article 8 of Directive (EU) 2019/1937 more narrowly and requires an own channel for every legal entity with at least 50 employees. As the Court of Justice has not ruled on the question, an additional local reporting route is advisable.
The joint reporting office under Section 14 (2) HinSchG is an expressly regulated form of resource sharing and is available only to employers with 50 to 249 employees. The group-level solution instead relies on mandating a third party under Section 14 (1) HinSchG and is not limited to that size bracket. In both cases accountability and follow-up measures remain with the individual employer.
The obligations continue to bind the individual employer, that is the respective subsidiary. Section 14 (1) sentence 2 HinSchG makes clear that mandating a third party does not remove the duty to take appropriate measures to stop a breach. Fines under Section 40 HinSchG – for example for failing to provide a reporting channel or for breaching confidentiality – are therefore imposed on the subsidiary, not on the central unit.

How preeco supports you

Learn how our software supports you with this topic.

Learn more